Impact
docx4j is an open-source Java library that processes OpenXML packages such as DOCX, PPTX, and XLSX files. Before version 11.5.14, the library's PropertyResolver and related helpers follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A DOCX containing mutually based styles causes the resolver to recurse indefinitely, leading to a StackOverflowError. When an untrusted document is processed—for example, during server-side conversion or table-of-contents generation—and this error occurs, a worker thread may terminate, degrade a thread pool, or cause a denial of service. The patch in 11.5.14 adds cycle tracking and exception handling to prevent the overflow.
Affected Systems
Applications that incorporate the docx4j library are vulnerable. The affected products are org.docx4j:docx4j-core and the Plutext distribution plutext:docx4j. Any deployment using a version older than 11.5.14 is subject to this flaw; versions 11.5.14 and later include cycle detection and exception handling that prevent the overflow.
Risk and Exploitability
The CVSS base score of 7.5 marks this as a high-impact denial of service vulnerability. An EPSS score of < 1% is now available, indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Attackers need only supply a crafted DOCX file to an application that processes documents with docx4j, a common scenario in server-side conversion or document generation. If not mitigated, a single malicious file can consume stack space in a worker thread and potentially bring down a web service or batch job.
OpenCVE Enrichment
Github GHSA